CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

556 vulnerabilities with CWE-346
CVE-2023-47194 HIGH
Trend Micro Apex One < 14.0.12737 - Privilege Escalation via Origin Validation Error
CVSS 7.8
CVE-2023-47193 HIGH
Trend Micro Apex One < 14.0.12737 - Privilege Escalation via Origin Validation Error
CVSS 7.8
CVE-2023-20275 MEDIUM
Cisco ASA/FTD - Privilege Escalation
CVSS 4.1
CVE-2023-49805 MEDIUM
Uptime Kuma < 1.23.9 - Origin Validation Error in WebSocket Connection
CVSS 6.0
CVE-2023-49803 HIGH
@koa/cors < 5.0.0 - Origin Validation Error via Missing Allowed Origin Check
CVSS 8.6
CVE-2023-28794 MEDIUM
Zscaler Client Connector <1.3.1.6 - Privilege Escalation
CVSS 4.3
CVE-2023-5859 MEDIUM
Google Chrome < 119.0.6045.105 - Domain Spoofing via Picture In Picture Security UI
CVSS 4.3
CVE-2023-5858 MEDIUM
Google Chrome < 119.0.6045.105 - Security UI Obfuscation via WebApp Provider
CVSS 4.3
CVE-2023-5853 MEDIUM
Google Chrome < 119.0.6045.105 - Security UI Spoofing via Crafted HTML Page
CVSS 4.3
CVE-2023-5851 MEDIUM
Google Chrome < 119.0.6045.105 - Origin Validation Error in Downloads
CVSS 4.3
CVE-2023-5718 MEDIUM
Vue.js Devtools - Unauthenticated Sensitive Data Exposure via postMessage API
CVSS 4.3
CVE-2023-28795 HIGH
Zscaler Client Connector <1.3.1.6 - Code Injection
CVSS 7.8
CVE-2023-44190 MEDIUM
Juniper Junos OS Evolved - Origin Validation Error in MAC Address Validation
CVSS 6.1
CVE-2023-44189 MEDIUM
Juniper Junos OS Evolved MAC Address Validation Origin Error
CVSS 6.1
CVE-2023-3654 CRITICAL
cashit! < 03.a06rks_2023.02.37 - Origin Validation Error via Host Header
CVSS 9.4
CVE-2023-2848 HIGH
movim < 0.22 - Cross-Site WebSocket Hijacking via Missing Header Validation
CVSS 8.0
CVE-2023-29505 MEDIUM
ManageEngine Network Configuration Manager 12.6.165 - Cross-site WebSocket Hijacking via WebSocket Endpoint
CVSS 4.3
CVE-2023-4045 MEDIUM
Firefox < 116 - Origin Validation Error via Offscreen Canvas
CVSS 5.3
CVE-2023-30949 MEDIUM
Palantir Slate < 6.207.0 - Origin Validation Error
CVSS 4.3
CVE-2023-2850 MEDIUM
NodeBB < 2.8.13 and 3.0.0-3.1.3 - Cross-Site WebSocket Hijacking via Missing Origin Validation
CVSS 4.7
CVE-2023-3581 MEDIUM
Mattermost 7.8.0-7.8.6 - WebSocket Origin Validation Bypass
CVSS 6.2
CVE-2023-21260 MEDIUM
Android - Origin Validation Error via Notification Access Permission Dialog
CVSS 5.5
CVE-2023-37210 MEDIUM
Firefox < 115.0 - Full-Screen Mode Spoofing via Alert and Prompt Calls
CVSS 6.5
CVE-2023-32223 HIGH
D-Link DSL-224 Firmware 3.0.10 - Authenticated Command Execution
CVSS 8.8
CVE-2023-32553 MEDIUM
Trend Micro Apex One < 14.0.12105 - Unauthenticated Sensitive Information Disclosure
CVSS 5.3
Details
Vulnerabilities 556